Which Files Were Affected by a Hack or Malware?

Inquiring minds want to know. They’ll be disappointed.

Once a hacker's had access to your machine, there's no guaranteed way to know everything they touched. I'll discuss why backups, not scans, are your best defense, and what to do if you don't have one.
A surprised Corgi looking at a Windows computer screen that says "HACKED!". The setting is a bright small business office.
(Image: Gemini)
Question: How can you determine which Windows files or registry settings have been compromised after your system has been hacked?

You cannot.

Once your computer has been hacked, it’s not your computer anymore.

That sounds serious because it is.

TL;DR:

After a hack

  • You cannot tell with certainty what a hack or malware may have affected.
  • The most common approach is to run repeated anti-malware scans.
  • The best solution is to revert to an image backup taken before the hack.
  • The painful solution is to reinstall and start over.

Hack fallout

Once your computer has been hacked, there is no approach that will tell you with 100% certainty what the hacker (or malware) changed.

Assuming a sufficiently proficient hack, the hacker will have had access to absolutely everything. They could change anything, and they could take steps to explicitly hide everything they changed.

There’s no way to know they haven’t hidden something you’ll never find. This is one of the reasons rootkits are so dangerous; they modify the system to hide their existence from standard file and folder listings.

Ask Leo! is Ad-Free!
Help keep it going by becoming a Patron.

Traditional solutions

What most people do after a hack is run scans with anti-malware tools or security packages, hoping they’ll catch whatever was corrupted and repair it. Often this means running complete scans with their existing utilities and using additional tools in the hopes they’ll discover more.

Generally, those tools catch a lot; it’s true. But there’s no guarantee they’ll catch everything.

Once you’ve taken the time to run all the tools, perform all the scans, and look in all the places that you learn of to look in, there’s still no way to know that you’ve found everything.1

You know you were hacked.

Yet regardless of the steps you take, you’ll never know you’ve cleaned up from it completely.

Pragmatic solution #1: backup to the rescue

We can’t prove that a computer is free of malware (even if it’s fresh out of the box), but there are steps we can take after a known compromise to improve the odds of having a clean machine.

The first approach is to back up your data to capture any recent changes, and then restore your system from a complete (or system-image) backup taken before the hack.

Of course, you can only use this solution if you’ve been creating complete backup images on a regular basis, and if you know when the hack happened. Most people fail the first criterion, sadly. The second can be difficult to determine, but more often than not, there’s a sign or symptom that made the compromise apparent.

Pragmatic solution #2: backup, reformat, reinstall

The second, more painful, approach is to back up your data2, and then:

  • Reformat and reinstall Windows from scratch
  • Reinstall all your applications from scratch
  • Carefully restore your data as you need it

If this feels painful, that’s because it is. It is time-consuming, but it’s often less time-consuming than struggling with a still-infected or unstable machine, and much more reassuring than not knowing if you’ve eliminated the threat.

After you’ve done so, make sure to implement that full system backup strategy to make recovery simpler should you ever get hacked again.

Do this

Don’t underestimate the risk of malware or the difficulty of removing it once it’s arrived. If you’re not already doing so, begin backing up regularly so you can recover more easily should it happen to you.

Footnotes & References

1: You can’t prove a negative.

2: Again, this should have been happening all along, but many people don’t do it.

Leave a reply:

Before commenting please:

  • Read the article.
  • Comment on the article.
  • No personal information.
  • No spam.

Comments violating those rules will be removed. Comments that don't add value will be removed, including off-topic or content-free comments, or comments that look even a little bit like spam. All comments containing links and certain keywords will be moderated before publication.

I want comments to be valuable for everyone, including those who come later and take the time to read.